📰 Key Takeaways
Ledger CTO Charles Guillemet posted on X on Monday, calling on security researchers to be more responsible when disclosing vulnerabilities. He noted that AI has made it much easier to find and exploit bugs, but some researchers rush to publish their findings before vendors have had a chance to patch them — a practice he called “attention farming with someone else’s risk.” Guillemet suggested researchers should privately report vulnerabilities first and agree on a fix timeline with the vendor before going public with details. The industry standard default is 90 days, though the actual number can flex depending on the severity of the bug and how much work the fix requires. Trezor’s head of security, Jan Komárek, also told Cointelegraph that the 90-day window is a commitment from the vendor, not just a constraint on researchers — he said researchers should reach out to vendors first and agree on a timeline, and if the vendor fails to ship a fix within that window, the researcher can still go public with the full details. Hardware wallet security has been in the spotlight lately, with Coldcard-related thefts now topping $100 million in losses, along with a data breach at a Trezor shipping vendor that exposed tens of thousands of customers’ personal information. Separate reporting says the Trezor data breach has grown to affect another 67,000 US customers.
💬 JudyAI Lab Take
Ledger CTO Charles Guillemet recently made a public call for security researchers to disclose hardware wallet vulnerabilities more responsibly — rather than rushing out details and turning someone else’s risk into a traffic farm.
This dust-up points to a trend AI builders should be paying attention to: AI is dramatically lowering the bar for finding and exploiting vulnerabilities. Bugs that used to require deep expertise to dig up are now much easier to surface. That means “disclosure speed” itself has become something that needs its own set of norms, not just a technical issue. Trezor’s head of security Jan Komárek’s proposed 90-day disclosure window — report privately first, agree on a fix timeline with the vendor, and only go public if that deadline is missed — offers a workable framework for responsible disclosure. The key is that the commitment cuts both ways: vendors are also on the hook to actually ship the fix in time. Combined with the recent string of hardware wallet thefts and data breaches, it’s clear that security processes haven’t kept pace with the attack surface AI is opening up.
If your project handles user assets or sensitive data, now’s a good time to check whether your team has a clear vulnerability reporting and fix-timeline process in place.
📅 Original Source
- Published: 2026-09-08T10:03
- Original article: https://cointelegraph.com/news/ledger-trezor-warn-ai-bug-hunters-attention-farming?utm_source=rss_feed&utm_medium=rss_tag_ai&utm_campaign=rss_partner_inbound